tommbtaq[.]vercel[.]app
“Poczta - Najlepsza Poczta, największe załączniki - WP”
tommbtaq.vercel.app — クローク済み · 到達可能. 詐欺タイプ: Credential Phishing. 証拠の概要: VirusTotal 17/91 (ADMINUSLabs, alphaMountain.ai, BitDefender, CyRadar, ESET); cloaking observed; PhishDestroy score 100/100. レジストラ: Vercel.
元のフォレンジック記録を保持するため、下の PhishDestroy AI 詳細分析は英語のままです。
This domain, tommbtaq.vercel.app, operates as a credential harvesting phishing site targeting users of a Polish webmail service. The page displays a fraudulent login interface under the title 'Poczta - Najlepsza Poczta, największe załączniki - WP,' designed to deceive visitors into entering their email credentials. Attackers use this tactic to collect usernames and passwords, which are then exploited for unauthorized access to accounts, financial fraud, or further phishing campaigns. The site poses a high risk due to its active status and targeted deception of users expecting legitimate email services. Analysis indicates the domain is hosted on Vercel Inc. infrastructure and resolves to the IP address 216.198.79.131, located within Amazon.com, Inc.'s AS16509 network in the United States. The SSL certificate, issued by Google Trust Services (WR1), does not mitigate the threat, as encryption is commonly used to lend false legitimacy to phishing sites. Security vendors have flagged the domain in 17 out of 95 detection engines on VirusTotal, and it appears on at least one security blocklist. The combination of active hosting, mimicked branding, and confirmed malicious detections confirms the domain's role in credential theft operations. If a user has visited tommbtaq.vercel.app or entered login details on the site, immediate action is required. First, change the passwords for any accounts using the same or similar credentials, prioritizing email, financial, and work-related services. Enable multi-factor authentication where available to prevent unauthorized access. Monitor accounts for suspicious activity, such as unauthorized logins or sent messages, and report any anomalies to the service provider. Users should also scan their devices for malware, as phishing sites may deliver additional payloads. Finally, report the domain to local cybersecurity authorities or incident response teams to aid in mitigation efforts.
脅威対応 Pipeline
公開ブロックリスト登録状況
VirusTotalによる分析
証拠および外部報告書
このサイトによって何か影響を受けましたか?
アカウント資格情報、個人情報、支払い情報を入力した場合、またはこのドメインからファイルをダウンロードした場合は、すぐに対処してください。インシデントを報告し、自分自身を守るのに役立つリソースを以下に示します。
お住まいの地域の当局へ報告してください
サイバー犯罪の公式連絡先 または 苦情草稿を作成する → を取得するには、国を選択してください。
任意のドメインを確認する
保存されたブロックリスト、WHOIS、DNS、および公開スキャン証拠を使用した脅威分析
今すぐスキャンフィッシングを報告する
不審なドメインを当社の脅威データベースに報告してください — コミュニティを守りましょう
レポートリアルタイム脅威情報フィード
最近のフィッシングレポートと観察された可用性の変化
監視最新情報を入手し、安全を確保しましょう
リアルタイムの脅威を監視するか、誤検知だと思われる場合はこのリストに異議を申し立ててください